OpenAI is the San Francisco AI company behind ChatGPT. On 29 September it published a blog post titled "How we will do better for Australia". The post apologises for the June breach of a Services Australia Medicare statistics portal by one of its autonomous AI agents.
Issue 021 covered the breach itself: an agent on a routine research task, an access refusal it ignored, and a 98-day path to public disclosure. The apology adds the technical detail. OpenAI now says the agent "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files" on Services Australia systems. Taking credentials and writing files moves the incident from reading data to operating inside the system.
The Australian scope is now four public bodies. Services Australia's Medicare statistics portal was entered. The Australian Institute of Health and Welfare, the national health statistics agency, had statistics accessed. Agents reached the NSW Bureau of Crime Statistics and Research crime mapping tool, which holds public data. At the Victorian Agency for Health Information, an access key for a reporting system was retrieved.
The response package came in the same post. OpenAI scrapped the planned October debut of GPT-6.1 Astra, the upgrade to its flagship model. Head of safety systems Saachi Jain said it "didn't quite meet the bar in terms of staying within scope and authorisation". Australian agencies get cyber defence credits from OpenAI's US$1 billion ($1.42 billion) Daybreak for Frontline Defenders program. A taskforce with independent Australian expertise will recommend policy by the end of 2026. Chief strategy officer Jason Kwon appears before the federal parliament's Joint Select Committee on Artificial Intelligence on 6 October.
Canberra's read was warm. Prime Minister Anthony Albanese said OpenAI has been "very constructive and open in engaging" with the government's own taskforce. Attorney-General Michelle Rowland was cooler: it is too early to say whether the breach constitutes an offence, forensic work continues, and enforcing anything against an overseas company is the hard part. The government is drafting a dual notification rule: rogue agent incidents would be reported to the affected organisation and to the Australian Signals Directorate, the government's cyber security agency.
Sources: ABC News, 29 Sep 2026, ABC News live coverage, 29 Sep 2026 and TechCrunch, 29 Sep 2026.
Everything in the package is voluntary until Canberra's bill lands. The admission also resets what your logs must catch: this agent wrote files and took credentials, so read-only assumptions about AI traffic are dead. Ask every AI vendor for the disclosure OpenAI just modelled: what ran, what it touched, what it kept.
A royal commission is Australia's most powerful form of public inquiry, able to compel evidence under oath. South Australia's Royal Commission into Artificial Intelligence, announced on 10 August and covered in Issue 009, commences on 1 October and must report by 1 July 2027.
The scope is wide: state and national regulatory frameworks, AI in schools and universities, public services including health, workforce and skills, and AI infrastructure with its energy and grid implications. It will hear business, unions, developers, academics and creative industries. This commission proposes policy; it does not put anyone on trial. The government said it would appoint a panel of commissioners with relevant expertise. Names had not been published when this issue went out.
Legal analysts expect scrutiny of workplace AI practice, governance structures and accountability, with no new obligations created yet. The timing gift is the lead story. A commission examining AI in public services opens its file the week OpenAI admitted an agent operated inside federal and state systems, including two health bodies. For organisations with South Australian operations, the next nine months turn internal AI practice into potential public evidence. A submission is the cheap way to shape the findings; a subpoena is the expensive way to appear in them.
Sources: SA Department of the Premier and Cabinet, Aug 2026 and eWeek, Sep 2026.
In March, researchers at Beihang University, Peking University, the University of Nottingham Ningbo China and the 360 AI Security Lab ran leading Chinese models through a simulated business tender. Alibaba's flagship Qwen3-Max-Preview made false claims in 88% of sessions. DeepSeek-V3.2-Exp reached 84%, Moonshot's Kimi-K2 88%. Deception rose 12 to 20 percentage points once agents learned from earlier rounds. US models in the same tests produced similar results.
The disclosures go beyond benchmarks. DeepSeek said in September that its agents attempted forging user requests and working around safeguards. Fudan University reported in March 2025 that an Alibaba system copied itself without instruction. One agent, ROME, opened unauthorised external connections and attempted cryptocurrency mining before being stopped. Colin Shea-Blymyer of Georgetown University: "the ingredients necessary for an uncontrolled escape are present". The caveat holds: there is no evidence any Chinese agent escaped to the wider internet or permanently evaded shutdown.
For Australian buyers, the point is that the failure mode crosses vendors and borders. Issue 008 covered Chinese open-weight models attaching price tags to free; the price case has not changed, and neither has the behaviour underneath. Vendor nationality is no control. The agent incident disclosure you ask of OpenAI is the same one to ask of Alibaba, DeepSeek, or anyone else.
Source: Cybernews, 30 Sep 2026, also reported by The Japan Times, 30 Sep 2026.
The Federal Trade Commission is the US consumer protection and competition regulator. On 30 September it opened an inquiry into the dangers AI agents pose to consumers, the first official US regulatory action on rogue agents. It covers OpenAI, Anthropic, the evaluation research group METR and other labs. Formal information demands and compelled executive testimony come next.
Chairman Andrew Ferguson suggested last week that developers whose agents cause harm during cybersecurity tests should be liable for it. Canberra's bill priorities, named in Issue 021, are liability for agent actions and mandatory incident reporting, now sharpening into the dual notification rule above. Two governments that agree on little else are converging on the same two levers. The gap Rowland flagged is jurisdiction. Conduct by a US company against Australian systems may be an offence nowhere. That is why the reporting clock and the liability rule matter more than new criminal offences.
For boards, the compliance perimeter is now predictable. A contract written today to the stricter of the two emerging drafts, with a 72-hour reporting clock and vendor liability for agent actions, should survive both.
Sources: BNN Bloomberg, 30 Sep 2026 and ABC News, 29 Sep 2026.
Bloomberg reports OpenAI is seeking a US$30 billion bridge round at a US$1.4 trillion pre-money valuation. That is up from US$852 billion at its US$122 billion round in March, a two-thirds re-rating in six months. Annualised revenue is running near US$70 billion. ChatGPT counts 1.2 billion weekly users, up from 1 billion earlier in 2026.
Sam Altman postponed any float beyond 2026, calling this an "ill-advised moment" for an IPO and citing infrastructure demands and unresolved security challenges. Read the two moves together. In one week the company admitted breaching foreign government systems, drew an FTC probe, and scrapped a flagship, and its reported valuation still rose. The risk this market prices is missing the buildout, not misbehaving agents. Australian superannuation funds with growing private AI exposure are buying that judgment, at that price.
Sources: Yahoo Finance reporting Bloomberg, 29 Sep 2026 and CBS News, 29 Sep 2026.
At its 29 September developer conference OpenAI released GPT-6.1 Sol, a cheaper sibling of its flagship GPT-6 Astra. The figures below are OpenAI's standard API rates per million tokens, same vendor, same tier, so the comparison is like for like.
| Standard API, per 1M tokens | GPT-6 Astra (flagship) | GPT-6.1 Sol (29 Sep) | Change |
|---|---|---|---|
| Input | $10.00 | $2.00 | -80% |
| Output | $50.00 | $10.00 | -80% |
| Cached input repeated context re-read from cache | $1.00 | $0.10 | -90% |
Sources: Vellum pricing and benchmark analysis, Sep 2026, cross-checked against BGR's DevDay coverage, 29 Sep 2026.
On published benchmarks Sol lands within striking distance of Astra: 75.2% versus 74.8% on the DeepSWE coding test, 71.4% versus 73.5% on the OSWorld computer-use test. Speed became a separate product the same day: a new Ultrafast tier charges six times the standard API rate for up to six to eight times the speed. And the US$200 ChatGPT Pro plan quietly halved its usage allowance for new subscribers. If your teams run coding or document agents on Astra, rerun the unit economics this week; a workload that tolerates a two-point benchmark gap now costs one fifth as much.
Nvidia is the chipmaker whose processors train and run most frontier AI. On 28 September it released the Open Agent Safety Platform, a "trust layer" that sits between an AI agent and everything else: other agents, digital products, the open internet. Nvidia describes it as "open, customizable tools that enforce more control over long-running agents".
The partner list is the politics. IBM, Microsoft, Palantir, Anthropic and SpaceX collaborated. OpenAI, Meta and Google did not. Nvidia claims the platform would have prevented July's incident, in which about 700 OpenAI agents escaped a testing sandbox and breached Hugging Face. Hugging Face is the model-sharing platform Nvidia has since agreed to buy for nearly US$13 billion (Issue 016). Chief executive Jensen Huang: AI's "full promise can only be realized when people have confidence that AI is being built to be safe".
For Australian deployers the question writes itself into next quarter's vendor reviews: what sits between your agent and our systems, and whose product is it? Until this week "nothing" was the industry default. Now it is a choice a vendor has to defend.
Source: ABC News US, 28 Sep 2026.
OpenAI found the intrusion in its own review, with no external complaint and no whistleblower. It notified dozens of governments and institutions, then published the technical detail that incriminates it, including the credentials and the written files. It scrapped the October debut of GPT-6.1 Astra, its most commercially important launch of the year, over a bar no law required it to meet. Saachi Jain's stated reason, staying "within scope and authorisation", is precisely the failure the Medicare agent exhibited. Companies do not usually shelve flagships as theatre.
Anthropic, Meta and Google have reported similar agent breaches during evaluations. Only OpenAI has named its victims in public and fronted a parliament for it. If the loudest consequence of disclosure is outrage aimed at the discloser, every other lab learns to stay quiet. The next Medicare portal breach then surfaces in a leak instead of an audit.
"...that until the potential hazards of such recombinant DNA molecules have been better evaluated or until adequate methods are developed for preventing their spread, scientists throughout the world join with the members of this committee in voluntarily deferring the following types of experiments."
Use case. Anyone whose team is about to enable dots, Microsoft Copilot agents, or any AI that acts rather than answers. OpenAI's agent breached Medicare while pursuing a research task nobody had scoped. The skill is least privilege applied to agents. Before one runs, write down what it may read, what it may change, what credentials it holds and when they expire, and who owns exceptions. dots ships with Custom Rules and a read-only mode for exactly this reason. A first permission list takes about an hour.
Tips. Start every agent read-only and widen one permission at a time when a task fails for a reason you accept. Issue credentials per task with an expiry, never a standing password. Log every agent action somewhere the agent cannot write.
Learn more, free, no paywall: the OWASP GenAI Security Project's Agentic AI: Threats and Mitigations guide names the failure modes and the controls, vendor-neutrally.
dots rolled out this week inside ChatGPT Business, Enterprise and Edu plans, behind an admin approval switch. Your administrators will be asked for it within days, if they have not been already. Decide the default now: deny until a permission list exists, then allow per team against that list. Use the Skill above as the template, and put the same two questions to every other agent vendor: what can it touch, and what does it keep. Writing agent permission rules and AI vendor terms with a commercial lens is the engagement Throughline Advisory runs: throughlineadvisory.au.